ProjectDiscovery's public nuclei-templates repository received new detection content for two newly tracked web application flaws: CVE-2026-26980 in Ghost CMS and CVE-2026-27493 in n8n. One pull request adds a template for a Ghost CMS SQL injection issue, with the contributor reporting validation against both vulnerable and patched targets to improve detection accuracy and reduce false positives. A second pull request adds coverage for a critical unauthenticated expression injection flaw in n8n Form nodes that can lead to remote code execution.
The n8n issue affects versions earlier than 2.10.1, 2.9.3, and 1.123.22, and the proposed template targets the /form/contact-us endpoint. The submission says attacker-controlled expressions in form fields are double-evaluated by the server, allowing arbitrary shell command execution; the detection logic verifies exploitation by looking for Linux uid/gid output after running a command in a controlled test. Both submissions were reported as validated on vulnerable and patched hosts and entered the standard GitHub review workflow, signaling rapidly emerging scanner coverage for high-impact Ghost CMS and n8n exposures.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
A new pull request proposed a Nuclei template for CVE-2026-27493, a critical unauthenticated expression injection flaw in n8n Form nodes that can lead to remote code execution via double evaluation of attacker-supplied expressions. The submission identified affected versions earlier than 2.10.1, 2.9.3, and 1.123.22, and said the template was validated on vulnerable and patched hosts.
A pull request was opened in the ProjectDiscovery nuclei-templates repository to add detection for CVE-2026-26980, described as a Ghost CMS SQL injection vulnerability. The contributor said the template was validated against both vulnerable and patched targets to confirm accurate detection.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.